ZimReaper is a browser-executed JavaScript infostealer targeting authenticated sessions in Zimbra Collaboration Suite’s Classic Web Client. It is associated with the Russia-aligned espionage actor TA488, also known as Void Blizzard and Laundry Bear. Campaigns observed from at least July 2025 targeted Ukrainian government entities and U.S. government, education, scientific, nuclear, and defense industrial base organizations.
ZimReaper is delivered through crafted HTML phishing emails exploiting CVE-2025-66376, a stored cross-site scripting vulnerability in Zimbra’s HTML sanitization. Opening or previewing a malicious message is sufficient to execute the payload, without clicking a link or opening an attachment. The exploitation chain uses fragmented markup, fake CSS import directives, and HTML comments to bypass sanitization. Later campaign variants incorporated XOR obfuscation to evade secure email gateways.
Once executing inside the authenticated webmail session, ZimReaper contacts command-and-control infrastructure and steals the victim’s email address, CSRF token, and browser-autofilled password. It queries Zimbra APIs for installation details and two-factor authentication recovery codes, and creates an application-specific password that provides persistent IMAP, POP3, or SMTP access without the normal two-factor authentication requirement. It systematically enumerates the organization’s Global Address List using two-character search combinations and attempts to export up to 90 days of accessible email. Credentials and other small data items are exfiltrated through DNS queries, while mailbox exports are transmitted as compressed archives through HTTP POST requests. ZimReaper is the predecessor of OWAReaper, a related JavaScript implant adapted to Outlook Web Access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
TA488 (Void Blizzard, Laundry Bear) was exploiting a previously unknown vulnerability against Zimbra mailservers for at least five months during 2025, until the issue was patched with CVE-2025-66376. | Proofpoint tracks this malware family as ZimReaper. ZimReaper then uses Zimbra APIs to conduct reconnaissance against the device and gather two-factor authentication codes.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Proofpoint tracks this malware family as ZimReaper. ZimReaper then uses Zimbra APIs to conduct reconnaissance against the device and gather two-factor authentication codes.
Proofpoint tracks this malware family as ZimReaper. ZimReaper then uses Zimbra APIs to conduct reconnaissance against the device and gather two-factor authentication codes.
TA458 and Void Blizzard exploited the “Half-click” vulnerability in Zimbra, Outlook Web Access, Roundcube, and SOGo to use ZimReaper and OWAReaper to collect credentials, contacts, and emails, and establish long-term persistence.
...ultimately resulting in the deployment of a JavaScript payload dubbed ZimReaper that's capable of harvesting 90 days of the victim's mail and other valuable data.
Once the JavaScript payload, dubbed ZimReaper by Proofpoint, executes, it performs the following malicious actions: steals the CSRF token and the browser's autofilled password, retrieves 2FA scratch codes, creates an app-specific password named ZimbraWeb, brute-forces the Global Address List, and exfiltrates 90 days of the victim's mail.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
La technique dite half-click exploit ne nécessite que l’ouverture ou la prévisualisation de l’email pour déclencher l’exécution du code malveillant, sans aucune interaction supplémentaire.
MITRE ATT&CK Mapping Tactic Technique ID Technique Name Initial Access T1190 Exploit Public-Facing Application
MITRE ATT&CK Mapping Tactic Technique ID Technique Name Credential Access T1003 OS Credential Dumping (Browser Passwords)
Impact: Full account takeover — attackers steal session tokens, 2FA codes, browser-saved passwords, the entire Global Address List, and up to 90 days of mailbox data.
Ping du serveur C2 pour confirmer l’exploitation ... Exfiltration via requêtes DNS ... Exfiltration des 90 derniers jours d’emails via HTTP POST
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously targeted Zimbra; mentioned as the predecessor or evolutionary basis of OWAReaper. The content provides no further functional details.
A malicious JavaScript payload used in attacks against Zimbra to harvest email communications and other sensitive data.
Credential and email collection malware used to harvest credentials, contacts, and emails and maintain persistence in webmail environments.
Previously used by TA488 against Zimbra email servers to steal emails, passwords, application passcodes and two-factor authentication codes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.